Current source addresses used when the Colewood Digital SEO Audit Tool retrieves a client website.
CURRENT ALLOWLIST
Give this page to the website or security team
Only the services below make direct requests to the website being audited from a stable, known address. Rules should be restricted to the audited hostname and normal web ports wherever possible.
TECHNICAL CRAWLER
DataForSEO On-Page crawler
Technical crawling, page parsing and screenshot collection
Match the client’s exact hostname and ports 80/443. Skip only the WAF, bot or rate-limit control preventing authorised retrieval.
02
Retest before crawling
Use the audit’s access check after the rule is active. A successful check confirms the site is returning readable pages before a paid crawl starts.
03
Remove it when agreed
The website owner may remove a temporary exception after audit collection is complete, unless ongoing monitoring has been agreed.
NO FIXED IP LIST
Services that cannot be allowlisted by one stable address
Google PageSpeed Insights
Google runs Lighthouse from data-centre infrastructure that can vary. Google does not publish a supported fixed PageSpeed source-IP allowlist. The page must be publicly reachable for a fresh lab test; historical CrUX field data may still be available separately.
OpenAI live page reading
Used only as supplemental evidence when requested by an authorised reviewer. It does not have an app-managed fixed source address. DataForSEO and the Colewood server remain the primary retrievers.
Search Console, GA4, Semrush, DataForSEO search datasets and Apify reputation collection call their providers’ APIs or public review platforms; they do not require an IP exception on the client website.